logo

Zebrocy used heavily by the Sednit group over last two years

ID: 14508a67-5536-450a-bc1d-2d7ab05ec2b0

STIX ID: report--14508a67-5536-450a-bc1d-2d7ab05ec2b0

Threat Score

88/100

Uploaded: 2026-08-07

Published Date: 2018-04-25

Last Modified Date: 2018-04-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ESET describes the Zebrocy malware family used by the Sednit (APT28/Fancy Bear) group: a multi-stage intrusion chain (Delphi downloader, AutoIt downloader, Delphi backdoor) delivered via malicious Office documents and archives that performs extensive reconnaissance and data collection and is used to deploy the Xagent backdoor on high-value targets (diplomats, embassies, ministries). The report documents evolving backdoor versions, TTPs, commands/capabilities, persistence mechanisms, and provides numerous IoCs (file hashes and C2 URLs) for detection and monitoring.